egeexyz / distro-delves

Checklists & Scripts to help test Linux distributions.
Other
33 stars 5 forks source link

QubesOS #56

Open aarroz opened 4 years ago

aarroz commented 4 years ago

Name & tl;dr

QubesOS - A security through isolation distro

Who is the target user?

According to it's website. It is made to support vulnerable users such as journalists and whistle-blowers who need security.

What platforms does it support?

x86_64 CPUs

What makes it special?

It's the only distro based on integrating virtual machines into it's desktop environment. It can run windows programs in a virtual windows machine and be integrated into the XFCE desktop environment. It's uses Xen for virtualization and Fedora as it's host OS.

egeexyz commented 4 years ago

Oh man this would make for a monstrous episode. Definitely something I'd want to cover on the show but I'm not sure.. how..

Reiddragon commented 3 years ago

Sidenote: to run QubeOS in a virtual machine you generally need to enable nested virtualisation (aka expose the virtualisation features in the CPU to the virtual machine) In VirtualBox that would be Enable Nested VT-x/AMD-V under System in the VM settings image

egeexyz commented 3 years ago

Planning to do this one next, on Jan 16th!

Lunarequest commented 3 years ago

The installation is a 100% offline, read up on the custom vm tools such as qvm-copy-to-vm which copies files to a target vm. it might be a good idea to state at the start and through. its not a beginner friendly distro by any means. it can't dual boot due to security issues brought with dual booting. you'll need to do a lot of research on the distro unlike the one before.

dominichayesferen commented 3 years ago

Egee's note to Egee: Might just kernel panic.

egeexyz commented 3 years ago

I booted up Qubes today only to discover it doesn't like the Gigabyte Brix' CPU timer for some reason; it kernel panics when trying to boot.

I ensured all the CPU settings were correct & virtualization was enabled and it still won't boot.

We can try QubesOS down the road when I get different hardware.